
3/5/2002

8/8/2024
CVE-2002-0257
First published: Fri May 03 2002(Updated: )
Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|
Usanet Creations Makebid Auction Deluxe | =3.30 | |
Apache Http Server | =1.3.19 | |
Apache Http Server | =1.3.20 | |
Apache Http Server | =1.3.18 | |
Apache Http Server | =1.3.17 | |
Apache Http Server | =1.3.22 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2002-0257?
CVE-2002-0257 is considered moderately severe as it allows remote attackers to exploit cross-site scripting vulnerabilities.
How do I fix CVE-2002-0257?
To fix CVE-2002-0257, you should implement input validation and sanitization for user-provided data in the affected form fields.
What software is affected by CVE-2002-0257?
CVE-2002-0257 affects version 3.30 of MakeBid Auction Deluxe and several specific versions of the Apache HTTP Server.
What types of information can be exposed by CVE-2002-0257?
CVE-2002-0257 can expose sensitive user information through various form fields like TITLE, EMAIL, and ADDRESS.
Is CVE-2002-0257 still a concern today?
While CVE-2002-0257 is an older vulnerability, it remains a concern for systems that have not been updated or patched.
- agent/references
- agent/type
- agent/remedy
- collector/mitre-cve
- source/MITRE
- agent/author
- agent/weakness
- agent/severity
- agent/last-modified-date
- agent/first-publish-date
- agent/event
- agent/description
- collector/nvd-historical
- agent/software-canonical-lookup-request
- collector/nvd-index
- agent/softwarecombine
- agent/tags
- agent/source
- vendor/usanet creations
- canonical/usanet creations makebid auction deluxe
- version/usanet creations makebid auction deluxe/3.30
- vendor/apache
- canonical/apache http server
- version/apache http server/1.3.19
- version/apache http server/1.3.20
- version/apache http server/1.3.18
- version/apache http server/1.3.17
- version/apache http server/1.3.22
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203